Login gives captcha on first attempt

Get help with installation and running phpBB 3.0.x here. Please do not post bug reports, feature requests, or MOD-related questions here.
Scam Warning
Forum rules
END OF SUPPORT: 1 January 2017 (announcement)
solutionsetcetera
Registered User
Posts: 16
Joined: Tue Jul 08, 2008 11:24 pm

Re: Login gives captcha on first attempt

Post by solutionsetcetera »

Thank you for this. I can now see all of the little low life's trying to do this.

underdead
Registered User
Posts: 16
Joined: Wed Nov 29, 2006 9:50 pm
Contact:

Re: Login gives captcha on first attempt

Post by underdead »

Thanks for the user log mod, that's a great idea and I've implemented it on my forum.
CougarCorner.com Your source for BYU Sports.

ObiDon
Registered User
Posts: 1
Joined: Thu Jan 13, 2011 6:40 am

Re: Login gives captcha on first attempt

Post by ObiDon »

Stoepsel wrote:...The log entries will be shown in ACP > Maintenance > User logs.
Nice!

sentinelace
Registered User
Posts: 151
Joined: Wed Nov 19, 2008 7:17 pm

Re: Login gives captcha on first attempt

Post by sentinelace »

I have this same problem but with all my users. What did you do to fix this?

Ryon
Registered User
Posts: 6
Joined: Sat Dec 10, 2005 4:43 pm

Re: Login gives captcha on first attempt

Post by Ryon »

I have to report that this is happening on my board too, after an upgrade to 3.8. One user has reported this twice in the last few weeks. There are no entries in the error log.

sentinelace
Registered User
Posts: 151
Joined: Wed Nov 19, 2008 7:17 pm

Re: Login gives captcha on first attempt

Post by sentinelace »

Mine is 3.0.8 which this is happening on too. I see a ton of reports. After I fixed mine, I now see a ton of spam users hitting my board. WTF?

Ryon
Registered User
Posts: 6
Joined: Sat Dec 10, 2005 4:43 pm

Re: Login gives captcha on first attempt

Post by Ryon »

It just happened to ME.

My login brought up the "You cannot log in without a password" page. But I just GAVE my password!

My board uses the qualifying question option instead of a captcha. Answering it correctly (I should know, I wrote it) brought up the "You exceeded the maximum..." page. But the maximum wrong guesses is set at THREE.

Plain vanilla v.3.0.8 w/prosilver Special Edition style. Running phpBB since 2002, updated to v.3.0.8 about a month ago.

sentinelace
Registered User
Posts: 151
Joined: Wed Nov 19, 2008 7:17 pm

Re: Login gives captcha on first attempt

Post by sentinelace »

my captcha was broken (only the 3d). Ran the phpmyadmin script to get back in and changed the captcha. Seems like hackers or spammers or both.

Scorpiuscat
Registered User
Posts: 108
Joined: Thu Jul 19, 2007 5:16 pm

Re: Login gives captcha on first attempt

Post by Scorpiuscat »

I too have seen this bug pop up since upgrading to 3.0.8.

its too many people to be a coincidence, there is a problem.
Please visit my Sci-Fi Website

Now Featuring over 1000 Free Flash Games!

Survival Bill
Registered User
Posts: 248
Joined: Tue Jun 12, 2007 3:03 am
Contact:

Re: Login gives captcha on first attempt

Post by Survival Bill »

I get lots of complaints from my users and it can happen several times in a row too has happened to me twice now....

solutionsetcetera
Registered User
Posts: 16
Joined: Tue Jul 08, 2008 11:24 pm

Re: Login gives captcha on first attempt

Post by solutionsetcetera »

I too still think there is a problem in 3.0.8. Never had complaints with 3.0.2. And after installing the user log mod above, I still see that folks are hitting the Captcha even though there are no attempts on their accounts from IP addresses other than their own.

Some folks are also complaining about being logged out in the middle of a session.

Ryon
Registered User
Posts: 6
Joined: Sat Dec 10, 2005 4:43 pm

Re: Login gives captcha on first attempt

Post by Ryon »

Is this consistent with others' experiences?

On login, users get the /ucp.php?mode=login page "You exceeded the maximum allowed number of login attempts. In addition to your username and password you now also have to solve the CAPTCHA below."

Solving the CAPTCHA, or in my case the written question, usually results in failure, though I have been successful in logging on at this point.

This happens to random registered users, and once it happens it will usually repeat. It took four weeks before it affected my account.

This happens whether you use the login in the upper right corner, or the login at the bottom of the page.

Nothing shows about this in the error log.

This seems to happen only to the 8.x version, independent of style used.

Pit$Bull
Former Team Member
Posts: 23099
Joined: Sat Dec 02, 2006 4:08 pm
Name: Can't Remember

Re: Login gives captcha on first attempt

Post by Pit$Bull »

This is not a new occurrence, it may just now happening to you.
It is happening world wide and not just to phpBB, and it's not version specific.
Hackers/spammers are trying to 'brute force' passwords. The protection built into phpBB is only allowing x number of attempts then the CAPTCHA is presented. ACP->main page->user registration settings
Maximum number of login attempts:
After this number of failed logins the user needs to additionally solve the anti-spambot task.
A strong password will also insure the 'brute force' will not succeed.

solutionsetcetera
Registered User
Posts: 16
Joined: Tue Jul 08, 2008 11:24 pm

Re: Login gives captcha on first attempt

Post by solutionsetcetera »

With all due respect… if the user log mod above is reliable, your explanation does not coincide with what is displayed in my user logs. The IPs listed with the log entries actually belong to the user, and after speaking with the user, I am confident he made no unsuccessful login attempts since his last session.

Perhaps we could get to the bottom of this if we had a way to log all login attempts for a period of time to see what is truly happening.

Pit$Bull
Former Team Member
Posts: 23099
Joined: Sat Dec 02, 2006 4:08 pm
Name: Can't Remember

Re: Login gives captcha on first attempt

Post by Pit$Bull »

I see no approved MOD listed.
You have been given a correct explanation of why it's been happening.

Locked

Return to “[3.0.x] Support Forum”